Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
https://plone.org/security/20131210/catalogue-exposure
http://www.openwall.com/lists/oss-security/2013/12/12/3
http://www.openwall.com/lists/oss-security/2013/12/10/15
Source: Mitre, NVD
Published: 2014-05-02
Updated: 2014-06-30
Base Score: 5.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N
Severity: Medium
Base Score: 5.4
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N